Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kkll5875

#49367of 56,334
5.4Total CVSS
Vulnerabilities · 1
PT-2024-30202
5.4
2024-08-26
Ruoyi Cms · Ruoyi Cms · CVE-2024-42913
**Name of the Vulnerable Software and Affected Versions** RuoYi CMS versions prior to 4.7.9 **Description** The issue is related to a SQL injection vulnerability. It can be exploited via the `job id` parameter at the "/sasfs1" endpoint. This allows an unauthenticated attacker to manipulate the `job id` and potentially compromise data. The vulnerability affects on-prem deployments. **Recommendations** For versions prior to 4.7.9, upgrade to a version greater than 4.7.9 to mitigate the risks. As a temporary workaround, consider restricting access to the "/sasfs1" endpoint or avoiding the use of the `job id` parameter until the issue is resolved.